{"id":"openSUSE-SU-2023:0058-1","summary":"Security update for phpMyAdmin","details":"This update for phpMyAdmin fixes the following issues:\n\nUpdate to 4.9.11:\n\n* Fix an XSS attack through the drag-and-drop upload feature\n  (PMASA-2023-01, CWE-661, boo#1208186, CVE-2023-25727) \n* Fix broken pagination links in the navigation sidebar\n* Fix syntax error for PHP 5\n* Fix hide_connection_errors being undefined when a controluser is set\n","modified":"2026-03-11T07:33:29.533752Z","published":"2023-02-22T13:26:27Z","related":["CVE-2023-25727"],"upstream":["CVE-2023-25727"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KQHBFWTBGODCBAQAKP2FMAYMJ2P7EKFE/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-25727"}],"affected":[{"package":{"name":"phpMyAdmin","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/phpMyAdmin&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.9.11-58.1"}]}],"ecosystem_specific":{"binaries":[{"phpMyAdmin":"4.9.11-58.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0058-1.json"}}],"schema_version":"1.7.5"}